Jailbreak iOS 4 on iPod touch 3G and iPod touch 2G MC Model

Sn0wbreeze 1.7 for 4.0 has been released. Just like PwnageTool4.0 / 4.01 for Macs, you can now create custom pwned / jailbroken ipsw files on Windows too which can now jailbreak all iOS devices (except iPhone 4) on iOS 4, including iPhone 3GS (newbootrom), iPod touch 2G (MC models) and iPod touch 3G. But there is a catch to it! You will need to have their SHSH blobs saved for iOS 3.1.2 in order to successfully jailbreak these devices on iOS 4. Also the jailbreak for iPhone 3GS (new bootrom), iPod touch 2G (MC models) and iPod touch 3G on iOS 4 will be tethered, which means whenever you turn off your phone, you will need to re-connect it to a computer to be able to turn it back on.

The step by step guide to jailbreak these devices is almost exactly similar to the last release. Simply follow the guide posted here to jailbreak your iPod touch on iOS 4 using Sn0wbreeze 1.7. Once you have created a custom firmware file, you can simply restore to it via iTunes 9.2. If there are any changes, we will redo the guide and post it again here.

UPDATE 1: ok guys, you will need to follow the following instructions to jailbreak iPod touch 3G and iPod touch 2G (MC models) on 3.1.2, or with 3.1.2 SHSH blobs saved.

Warning Note: All the standard warnings apply. This is for advanced users only. Only proceed if you think you know your iPhone/iPod touch inside out.

**BEFORE PROCEEDING, ENSURE THAT YOU HAVE YOUR iPod/PHONE BACKED UP!** THIS TUTORIAL ASSUMES YOU ARE ALREADY ON 3.1.2!Q: Why not 3.1.3???A: The exploit used is closed in 3.1.3 and beyond. ——- WHAT YOU WILL NEED:* An iPhone 3G[S] or iPod Touch 2G MC or iPod Touch 3– new bootrom * 3.1.2 already installed or 3.1.2 installed via SHSH blobs. <– Broken blackra1n’d devices will work. (Especially if Spirit messed you up!). * Payload Pwner-r5 (http://www.mediafire.com/?zgzynznwn0y) * sn0wbreeze V1.7 * iBooty V1.5 (http://www.mediafire.com/?mmnjti0midn) * 3.1.2/4.0 firmware downloaded. * iTunes 9.2 Installed ——- STEP A : Pwning iBootI : Download this easy tool here — Payload Pwner-r5 (http://www.mediafire.com/?zgzynznwn0y) // It will help you create the payload. II : Extract it to a directory and run Pwner.exe **SAVE THE PAYLOAD WHERE iBooty is.**——- STEP B : Making a Custom IPSWI : Download sn0wbreeze V1.7 II : USE EXPERT MODE! III : In General, Checkmark "Disable NOR Flash" <– THIS IS ESSENTIAL!!!! IV : Build it. It will be on your Desktop. **CUSTOM BOOT LOGOS THAT ARE MADE IN sn0wbreeze WILL NOT WORK ON NEW BOOTROMS!***Mac Users : PwnageTool does not have this option. I don’t think it will ever be in there. Use a Windows Virtual Machine or friends PC to create your firmware.* ——- STEP C: iBooty Prep.Most of you know of the utility "iBooty" that I made for Aki_nG. It will work as long as you place all of the correct files there. I : Download iBooty GUI here — iBooty V1.5 (http://www.mediafire.com/?mmnjti0midn) and Extract it. II : Extract your Custom IPSW created by sn0wbreeze with 7-Zip or another un-archiver. III : Grab the kernelcache and bring it into the same folder as ibooty. Also grab iBEC from the folder "Firmware\dfu". Aswell as DeviceTree from the folder "Firmware\all_flash\all_flash.n88ap.production\DeviceTree.n88ap". IV : * Rename your Kernel 4.0-Custom to "kernel.40" * Rename your iBEC 4.0-Custom to "ibec.40" * Rename your DeviceTree 4.0-Custom to "devtree.40" ***MAKE SURE YOU REMOVE THE .img3/.dfu/etc extensions!***====== Your folder should look like this : – iboot.payload <– Created with Payload Pwner. – devtree.40 <– Grabbed from Custom IPSW made by sn0wbreeze. – ibec.40 <– Created with Payload Pwner. – bspatch.exe <– Comes with iBooty. – iBooty.exe <– Comes with iBooty. – kernel.40 <– Grab from Custom IPSW made by sn0wbreeze. – sn0w.img3 <– Comes with iBooty. – wait.img3 <– Comes with iBooty. ====== ——- STEP D: Restoring to 4.0 + Booting——- *MAKE SURE YOU ARE ON 3.1.2 WHEN DOING THIS* I : Run iBooty and Select "Prepare Device for Custom Firmware". Make sure that your device is in Recovery Mode (The one with the iTunes Connect Logo). Run the Process and if you see the image, you can proceed! II : Now open iTunes and restore to the custom ipsw. ***WHEN DONE, YOUR DEVICE WILL GO INTO RECOVERY MODE. IT WONT BOOT.*** ——- STEP E : BootingI : Just Re-Run iBooty and select "Boot It". If all goes well it will boot!

in the /dfu etc extension remove all the .img3 extensions on the files so they are in raw format.. hope this helps

Rcoffman_3

I’ve heard this works however I’m experiencing a problem with it myself .. getting an error 17 and doesn’t seem to be a whole lot of information about this particular error so waiting to see if someone can figure out a solution to it..

Rcoffman_3

Go to where it says build and click it and it will start building the custom firmware and when it’s finished it will be on your desktop.

Hope I helped .. Rob

Rcoffman_3

make sure you are running iboot in the same directory as where the firmware files are located..

Rob

Aftermathfan1

i dont know if this will be of any help to other ipod touch 2g mc owners..

but i was also stuck on the connect to itunes logo, with a battery showing at the top..

on itunes, i backed up my ipod touch after blackrain jailbreak on 3.1.2

i went through with this guide, using the 1.5 payload pwn, and 1.5 ibooty.

then AFTER the guide,

i deleted the payload and ibooty stuff, and i replaced the ibooty with 1.6, and i replaced payload with 1.6 and i re-did the payload process again..

while my ipod was stuck on the connect to itunes screen, with the battery showing at the top right,i restored the backup i made from before…it attempted to reboot,and then thats when i tried the ibooty “booty callz” once more, with success..

bruce lee

i just wait for new spirit because my soft version is 4.0 and i have ipod touch 3g or 2g mc model 😀

Why

can you use the app called bump to send cydia?

Cougarmauler77

so when i get to the part where i have to browse for the 4.0 IPSW file i cant find it! please help!

Unbreakable

is it working ?!

Nicky

Thanks worked perfectly

Luizrogeriocn

Thank you very much, i have iPod Touch 2G MC MODEL and it is jailbroken now running IOS 4.0! For the ones who get the Connect to iTunes img with battery at the top just wait and it'll boot!But i have one question, is this thetered jailbreak?Thanks again! =D

Jose

hi my ipod touch 3g is on 3.1.3 spirited i cant downgrade to 3.1.2 because of shshs but on cydia it says the device has shshs for ios 4 what does it really mean?

Unan_softy

how can i jail break my ipod touch 3g 4.0 i just bought it last week.. and did not under go in any jail breaking process… can any one help me?

Mechey_mechey

how to jailbreak it?

Al Wakelin

you need shsh blobs on 3.1.2 – there different on 4.0 🙁

Flo1006

I have a question. My iPod Touch 3g is already jailbroken on 3.1.2. If i jailbreak it for 4.0, will all downloaded apps with install0us be deleted?

Asfsafda

yeah

Sundberg D

I have a 3gs 3.1.3 jailbroken with spirit. I did an update to 4.0.1 and tried to jailbreak with jailbreakme.com. After the jailbreak it said “no service” and when I put the correct sim, which the phone is locked to, it worked. I read on forums that some people needed to restore before update and jailbreak. I did this and all of a sudden I had 4.0.2.
My question; will there be a jailbreakme for 4.0.2?

Elvin Gutierre34

save it to your desktop

Sam_madeinhell

hey is this a tethered jailbreak if so do i do this whole thing again every time i turn my ipod off?

layven

mine is a mc model will it work ??????????????????????

Air_Ipod

so is it atm imposibble to jailbreak ipod touch 3.1.3 without 3.1.2 shsh blobs?